CVE-2020-8515
01.02.2020, 13:15
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.
Vendor | Product | Version |
---|---|---|
draytek | vigor2960_firmware | 1.3.1:beta |
draytek | vigor300b_firmware | 1.3.3:beta |
draytek | vigor300b_firmware | 1.4.2.1:beta |
draytek | vigor300b_firmware | 1.4.4:beta |
draytek | vigor3900_firmware | 1.4.4:beta |
𝑥
= Vulnerable software versions
References